๐ง๐ฌ
HighWay
2026-10-05 15:55:08
(19 seconds ago)
34.95.220.22 - - [05/Oct/2026:15:55:02 +0000] "POST /lib/terminal-xhr.php HTTP/1.1" 404 4759 "-" "Du ...
show more
34.95.220.22 - - [05/Oct/2026:15:55:02 +0000] "POST /lib/terminal-xhr.php HTTP/1.1" 404 4759 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.95.220.22 - - [05/Oct/2026:15:55:02 +0000] "GET /kr8bnapv4qp8l42a130b HTTP/1.1" 404 4759 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.95.220.22 - - [05/Oct/2026:15:55:03 +0000] "POST /graphql HTTP/1.1" 404 770 "https://vhelectronics.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.95.220.22 - - [05/Oct/2026:15:55:03 +0000] "GET /wp-json HTTP/1.1" 404 770 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
34.95.220.22 - - [05/Oct/2026:15:55:03 +0000] "POST /api/graphql HTTP/1.1" 404 770 "https://vhelectronics.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-10-05 15:22:23
(33 minutes ago)
34.95.220.22 - - [05/Oct/2026:16:22:23 +0100] "GET /av954ifv0p8cxr7gb9b9 HTTP/1.1" 404 6447 "https:/ ...
show more
34.95.220.22 - - [05/Oct/2026:16:22:23 +0100] "GET /av954ifv0p8cxr7gb9b9 HTTP/1.1" 404 6447 "https://trailrides-wales.com/av954ifv0p8cxr7gb9b9" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
...
show less
Bad Web Bot
๐ฉ๐ช
svr
2026-10-05 15:01:37
(53 minutes ago)
Abusive Automated Web Scanner
Web App Attack
๐ฉ๐ช
thesimonmanuel
2026-10-05 14:53:47
(1 hour ago)
34.95.220.22 - - [05/Oct/2026:20:23:46 +0530] "GET /.ssh/id_rsa HTTP/2.0" 404 13392 "-" "Mozilla/5.0 ...
show more
34.95.220.22 - - [05/Oct/2026:20:23:46 +0530] "GET /.ssh/id_rsa HTTP/2.0" 404 13392 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
show less
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-10-05 14:48:25
(1 hour ago)
crowdsecurity/http-probing detected by CrowdSec
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 14:47:00
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.95.220.22 (22.220.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.220.22 (22.220.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 10:46:54.465057 2026] [security2:error] [pid 29736:tid 29736] [client 34.95.220.22:51896] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tek-front.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tek-front.com"] [uri "/z9x8c7v6b5-debug-trigger-tek-front.com"] [unique_id "asO4XnA80UTXmh9XHxMxIgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 13:10:33
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.95.220.22 (22.220.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.220.22 (22.220.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 09:10:27.172377 2026] [security2:error] [pid 19827:tid 19827] [client 34.95.220.22:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rodrigoaldecoa.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rodrigoaldecoa.com"] [uri "/z9x8c7v6b5-debug-trigger-rodrigoaldecoa.com"] [unique_id "asOhwyzg5dN9n6Hgp1pfIAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-10-05 13:10:07
(2 hours ago)
Web App Attack
๐ฉ๐ช
rh24
2026-10-05 12:37:18
(3 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.95.220.22 (BR/Bra ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.95.220.22 (BR/Brazil/22.220.95.34.bc.googleusercontent.com)
show less
Bad Web Bot
๐ซ๐ท
regishoussin
2026-10-05 12:31:25
(3 hours ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-10-05 12:31 UTC.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 12:20:56
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.95.220.22 (22.220.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.220.22 (22.220.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 08:20:50.837546 2026] [security2:error] [pid 977:tid 977] [client 34.95.220.22:43040] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||postermodelsworldwideinc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "postermodelsworldwideinc.com"] [uri "/z9x8c7v6b5-debug-trigger-postermodelsworldwideinc.com"] [unique_id "asOWIkxv_JbpuISarrjmawAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 12:02:11
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.95.220.22 (22.220.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.220.22 (22.220.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 08:02:03.806052 2026] [security2:error] [pid 8662:tid 8676] [client 34.95.220.22:56044] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||peluqueriabuhos.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "peluqueriabuhos.com"] [uri "/z9x8c7v6b5-debug-trigger-peluqueriabuhos.com"] [unique_id "asORu5p9dkGbzV87-vnquwAAAUs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
dineshskt4all
2026-10-05 11:56:00
(3 hours ago)
34.95.220.22 - - [05/Oct/2026:11:55:58 +0000] "POST / HTTP/1.1" 403 3258 "-" "Mozilla/5.0 (compatibl ...
show more
34.95.220.22 - - [05/Oct/2026:11:55:58 +0000] "POST / HTTP/1.1" 403 3258 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
...
show less
IoT Targeted
๐ฉ๐ช
on-com
2026-10-05 11:38:41
(4 hours ago)
URL scan
Brute-Force
Web App Attack
๐ซ๐ท
cityhunter_rhone
2026-10-05 10:35:03
(5 hours ago)
Mercurius trap auto report | source=TRAP_AND_APACHE_DENIED | last_seen=2026-10-05 12:30:33 | hits_40 ...
show more
Mercurius trap auto report | source=TRAP_AND_APACHE_DENIED | last_seen=2026-10-05 12:30:33 | hits_403=72 | hits_404=0 | ip=34.95.220.22 | sample_uri=/lib/terminal-xhr.php
show less
Port Scan
Hacking
Web App Attack